# Web Application Security Fundamentals Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/web-application-security-fundamentals-self-paced>

## Overview

This is an intermediate course built to span two audiences that are usually trained apart. There is enough technical grounding for the people who build and configure web applications, and enough plain-language framing for the system owners, ISSOs and contracting staff who oversee them without writing code. Shared vocabulary is the whole point of the design, because most web application security training targets developers only, whereas here a developer, a system owner and an ISSO can take the same course and come away able to hold the same conversation. There is no lab, by design rather than by omission: nothing needs provisioning and there are no technical prerequisites, which is what makes it assignable to oversight staff and developers at once. Reinforcement comes instead from drag-and-drop matching and sequencing and from scenario prompts asking "given this situation, what is the most appropriate action", and no lab environment is needed for any module or for the final assessment.

Topics are anchored to federal policy rather than taught generically. The first module is intentionally policy-heavy so later technical modules can refer back to it, covering FISMA, the Risk Management Framework and the authorization process, Executive Order 14028 and its amendments, and Cybersecurity Framework 2.0, and it teaches a skill that is rare even in commercial training — recognizing when a memorandum has been superseded — and why confirming currency matters before leaning on a policy for compliance. The second module is organized around the OWASP Top 10, 2025 edition, and concentrates on recognizing risk rather than writing exploit code, after which the course moves through the secure development lifecycle and the Secure Software Development Framework, into identity, access control and data protection with Zero Trust and FIPS-validated encryption, and finishes on continuous monitoring, event logging and incident reporting. Each module carries ungraded quick checks, and a graded final assessment covers all five modules proportionally, weighted toward applying concepts rather than recalling facts, at 70% to pass with unlimited retakes.

## What you'll learn

- Explain why web application security is a shared responsibility across technical and non-technical federal staff
- Identify the federal laws, executive orders and NIST, OMB and CISA guidance that govern federal web applications
- Recognize when a policy or memorandum has been superseded, and why confirming currency matters
- Recognize the most common categories of web application vulnerability and the risk each poses to federal systems and data
- Describe secure software development lifecycle practices and how they reduce risk
- Apply core secure-coding principles including input validation, output encoding, least privilege, secure defaults and failing securely
- Manage risk from third-party and open-source components
- Explain identity, access control and data protection principles, including Zero Trust and FIPS-validated encryption
- Describe federal expectations for continuous monitoring, event logging and incident reporting
- Apply all of the above to realistic scenarios without needing a technical lab

## Prerequisites

Basic familiarity with general cybersecurity concepts and everyday web application use. No development experience required.

## Curriculum

#### Module 1

- Foundations of Web Application Security and the Federal Policy Landscape
- What a web application is and why it is a common attack surface
- The CIA triad applied to federal systems
- Threat actors from nation-state to insider
- Shared responsibility across developers, system owners, ISSOs and users
- FISMA, the Risk Management Framework and the authorization process, Executive Order 14028 and its amendments, and Cybersecurity Framework 2.0
- How to tell when a policy has been superseded

#### Module 2

- Common Web Application Vulnerabilities
- How the OWASP Top 10 is developed and why federal secure-coding guidance references it
- The 2025 edition categories including broken access control, cryptographic failures, injection, insecure design and misconfiguration, vulnerable and outdated components, authentication failures, server-side request forgery, and logging and monitoring failures
- Why each is consequential for federal systems

#### Module 3

- Secure Development Practices and the Secure SDLC
- The phases of a secure development lifecycle
- Input validation, output encoding, least privilege, secure defaults and failing securely
- Security requirements and threat modeling before code is written
- Static and dynamic testing at a conceptual level
- Open-source and software supply chain risk
- How secure development supports the path to an authorization to operate

#### Module 4

- Authentication, Access Control, and Data Protection
- Authentication versus authorization
- Multifactor authentication and federal digital identity assurance levels
- Role-based and attribute-based access control and least privilege
- Zero Trust principles applied to web applications
- Protecting data at rest and in transit including FIPS-validated encryption
- Common mistakes such as exposing sensitive data in URLs and weak session management

#### Module 5

- Monitoring, Incident Response, and Ongoing Compliance
- Continuous monitoring under the Risk Management Framework
- Federal event-logging expectations for incident investigation
- Recognizing and reporting a suspected web application incident
- How FISMA reporting and periodic reauthorization keep systems accountable
- What any employee should do on suspecting a compromise

## Pricing

**Tuition:** $899
